Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Annotations already cover the safety profile (readOnly, idempotent, non-destructive, closed-world). The description adds non-obvious behavioral guidance: results are evidence not permission, a missing plan must not be used to invent faster replies or channels, and evaluate_support_promise must gate any claim. That is genuine added context beyond the structured hints.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.